CSRD and the ESRS
The Corporate Sustainability Reporting Directive requires in-scope companies to report sustainability information according to the European Sustainability Reporting Standards (ESRS), in the management report, in a machine-readable format, and subject to assurance.
The ESRS comprise cross-cutting standards (ESRS 1 general requirements, ESRS 2 general disclosures) and topical standards across environment (climate, pollution, water and marine, biodiversity, resource use and circular economy), social (own workforce, workers in the value chain, affected communities, consumers and end-users) and governance (business conduct).
Two features change how the work is organised. Reporting is subject to assurance, beginning with limited assurance — meaning every number needs a defensible trail. And the scope is determined by a double materiality assessment, so the assessment itself becomes an auditable artefact rather than an internal planning exercise.
Note that CSRD scope and timing have been subject to legislative amendment, including the 2025 "omnibus" proposals. Confirm your applicable wave and first reporting year against the current national transposition rather than the original directive text.
Double Materiality Is a Risk Assessment
Double materiality asks two questions:
- Impact materiality — how the company affects people and the environment, considering severity (scale, scope, remediability) and, for potential impacts, likelihood.
- Financial materiality — how sustainability matters affect the company's development, performance and position, considering magnitude and likelihood.
A matter is material if it meets either test. In practice both are risk assessments with the same structure your enterprise risk process already uses — likelihood against consequence, scored on defined scales, with thresholds.
Teams that run double materiality inside their existing ERM methodology finish faster and produce defensible output, because the scales, escalation thresholds and review cadence are already agreed and already audited. Teams that invent a parallel scoring system spend the first two months arguing about scales, and then have to defend a bespoke method to an assurance provider.
The assessment must be documented: stakeholder engagement, the matters considered, scoring, thresholds, and the resulting list of material topics with the disclosures they trigger.
Scope 1, 2 and 3 Emissions
The GHG Protocol splits emissions into three scopes:
| Scope | What it covers | Typical difficulty |
|---|---|---|
| 1 | Direct emissions from owned or controlled sources | Manageable — fuel and refrigerant data |
| 2 | Indirect emissions from purchased energy | Manageable — needs location- and market-based figures |
| 3 | All other value-chain emissions, across 15 categories | Hard — depends on data you do not control |
Scope 3 is where credibility is won or lost. Two calculation approaches dominate: spend-based (activity spend × emission factor — quick, low accuracy) and activity-based (physical quantities × factors — more accurate, more data). Most organisations begin spend-based and migrate the material categories to activity-based over time.
What assurance requires is not perfect data. It is disclosed method, disclosed factor source and version, and consistency between periods, with restatements visible as restatements. An estimated figure with a documented method is defensible; a precise-looking figure with no provenance is not.
GRI, SASB, TCFD and SFDR
GRI is the most widely used global standard for impact reporting, organised as universal, sector and topic standards, with a multi-stakeholder audience.
SASB standards, now under the ISSB, are industry-specific and investor-focused, concentrating on financially material sustainability topics. They map closely to ESRS financial materiality.
TCFD structured climate disclosure across governance, strategy, risk management, and metrics and targets. The TCFD itself has been disbanded, with monitoring transferred to the ISSB — but its four-pillar structure survives inside IFRS S2 and the ESRS climate standard, so work done against TCFD is not wasted.
SFDR applies to financial market participants and advisers, governing sustainability-related disclosures for products and entities, including principal adverse impact indicators.
Most organisations report against several. The mappings between them are well established, so the practical approach is to collect each datapoint once and map it to every framework that requires it — the same logic that applies to controls in information security compliance.
Building the Evidence Trail
Sustainability data is the least mature data in most organisations, and it is now subject to assurance. What that demands:
- Provenance for every figure — source system or supplier, submission date, and the request it answers.
- Method and factor version recorded alongside estimates.
- Immutability — submissions versioned, never overwritten.
- Controls over completeness and accuracy, with owners, frequencies and test results, exactly as for financial data.
- Linkage to the risk register, so a supplier data failure is an assessed risk rather than a red cell on a dashboard.
Supplier ESG data is the weakest link, because it originates outside your control environment. The machinery that already governs security questionnaires applies unchanged.
How ActiveERM Supports ESG Reporting
The ESG module runs double materiality on the same methodology as the risk register, tracks Scope 1, 2 and 3 with recorded methods and factor versions, and maps datapoints to ESRS, GRI, SASB and TCFD so each is collected once.
Because it sits on the GRC platform, sustainability controls live in the same library as security and financial controls, supplier ESG assessments resolve to the same third-party record as security and procurement assessments, and the assurance provider pulls from one evidence store.
See also our guides to GRC and ESG integration and getting started with ESG reporting.